Hi all, I have cluster SRX550 and formed dynamic VPN via J-web VPN Wizard.
Now I can use Pulse Secure to connect this VPN form outside network, after connect VPN I get the ip address 192.168.168.x/24
However, I cannot access the internal vlan 128 network after connect VPN (fail to ping 172.16.128.1)
Please find SRX550 config below for your reference.
set security dynamic-vpn clients wizard-dyn-group remote-protected-resources 192.168.168.0/24
set security policies from-zone WAN to-zone Internal policy policy_in_wizard_dyn_vpn match source-address any
set security policies from-zone WAN to-zone Internal policy policy_in_wizard_dyn_vpn match destination-address any
set security policies from-zone WAN to-zone Internal policy policy_in_wizard_dyn_vpn match application any
set security policies from-zone WAN to-zone Internal policy policy_in_wizard_dyn_vpn then permit tunnel ipsec-vpn wizard_dyn_vpn
set access profile remote_access_profile address-assignment pool dyn-vpn-address-pool
set access address-assignment pool dyn-vpn-address-pool family inet network 192.168.168.0/24
set access address-assignment pool dyn-vpn-address-pool family inet xauth-attributes primary-dns 8.8.8.8/32
set security zones security-zone Internal interfaces reth1.128 host-inbound-traffic system-services all
set security zones security-zone Internal interfaces reth1.128 host-inbound-traffic protocols all
set interfaces reth1 unit 128 vlan-id 128
set interfaces reth1 unit 128 family inet address 172.16.128.1/24
set vlans vlan128 vlan-id 128
May I know is there missed some config (maybe policy or route) ? How can I access the vlan 128 network after connect VPN form outside network? Thanks!!